An Iranian security firm reported a firmware-level rootkit targeting HP Integrated Lights Out (iLO) that could repeatedly wipe disks on compromised servers, creating persistent and difficult-to-diagnose outages. The implant was described as operating below the host operating system at the server-management firmware layer, combining stealth and persistence with a destructive wiper capability that could re-destroy the same systems after recovery efforts. Researchers noted the malware’s potential impact on sensitive servers, data centers, and critical infrastructure environments because compromise of iLO can survive conventional remediation on the host.
Open-source reporting tied the activity to attacks affecting organizations in Iran, while separate research associated the campaign with the Indra threat actor. However, public evidence remained limited: reporting cited sparse technical indicators and did not support high-confidence attribution despite at least one artifact reportedly matching the malware’s described behavior. The case highlighted the operational risk of out-of-band management compromise, where attackers can pair firmware persistence with destructive actions to cause recurring service disruption rather than a one-time wipe.

See attribution, scope, and your downstream exposure.
1 event from the most recent confirmed update back to the earliest known activity.
On 28 December 2021, Iranian security company Amnpardaz Soft published a report describing a firmware-level rootkit targeting HP Integrated Lights Out (iLO) and designed to repeatedly wipe disks on infected systems. The report did not include indicators of compromise, and the available evidence did not support confident attribution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.